I'm running Declude v1.76i14, and it is my understanding that this version
will lookup the virus name via DNS to see if it's forging or not. It
appears that the below virus is forging, but I believe my logs show it
trying to send a notification to the sender. Is this common behavior on
I'm running Declude v1.76i14, and it is my understanding that this version
will lookup the virus name via DNS to see if it's forging or not.
Correct.
It appears that the below virus is forging, but I believe my logs show it
trying to send a notification to the sender.
We've updated our server
[EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Saturday, July 05, 2003 11:29 PM
Subject: RE: [Declude.Virus] FORGING VIRUS
Hi;
Just in case Scott is taking a day off...
The way we do this is by first adding:
FORGINGVIRUS Braid
FORGINGVIRUS Bridex
FORGINGVIRUS Bugbear
FORGINGVIRUS Hybris
sorry if this is a trivial question, but is there a
skipifforgingvirus option ?
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.Virus mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type
the from adress still shows in the header
is is the forged adress?
is there a way to eliminate this?
I have customers fighting each other because of declude notifications!
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
This E-mail came from the
the from adress still shows in the header
is is the forged adress?
is there a way to eliminate this?
No, that can not be changed (Declude never modifies any of the E-mail
headers). One option would be to remove the %HEADERS% variable to
eliminate the headers from the notifications.
I have